GHSA-jf5f-h3wr-j666

Suggest an improvement
Source
https://github.com/advisories/GHSA-jf5f-h3wr-j666
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-jf5f-h3wr-j666/GHSA-jf5f-h3wr-j666.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-jf5f-h3wr-j666
Aliases
Published
2022-05-13T01:28:41Z
Modified
2024-02-16T08:18:36.615408Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
SQL Injection in Zenario 7.1-7.6
Details

Zenario v7.1 - v7.6 has SQL injection via the Name input field of organizer.php or admin_boxes.ajax.php in the Categories - Edit module.

Database specific
{
    "nvd_published_at": "2018-01-22T01:29:00Z",
    "cwe_ids": [
        "CWE-89"
    ],
    "severity": "HIGH",
    "github_reviewed": true,
    "github_reviewed_at": "2023-07-07T18:49:00Z"
}
References

Affected packages

Packagist / tribalsystems/zenario

Package

Name
tribalsystems/zenario
Purl
pkg:composer/tribalsystems/zenario

Affected ranges

Type
ECOSYSTEM
Events
Introduced
7.1
Last affected
7.6

Affected versions

7.*

7.5.40440
7.5.41006
7.5.41499
7.5.41633
7.5.42085
7.5.42990
7.5.47180